Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

231–240 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#231

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

Hasn’t Google been parsing Google Photos images, email content, and pretty much everything else since forever? Do you just stay off of smartphones and cloud platforms entirely?

They scan things I send them.

They don't (publicly announce that they) scan things on my device.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#232

Earlier quoted context omitted.

On phones: I'm considering a Pixel device with https://calyxos.org/ The main limitations will be the featureset of MicroG (no ~maps~/wearOS/auto). Possible issues with important apps like those for banking. On cloud: Synology Diskstation is amazing. Only use it through a local VPN though. edit: maps work (see reply)

> no maps I don't experience any issues using mapping apps on Android with microG instead of Google Play Services. Closed source navigation apps including Google Maps, HERE WeGo, and Magic Earth work just fine. Open source navigation apps like Organic Maps and OsmAnd also work with no problems.

I have found that my Pixel with CalyxOS and microG doesn't have any text to speech engine. So the maps apps work, but with no turn by turn audio.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#233
post #185

Earlier quoted context omitted.

What are the ramifications that I "do not understand"? I will repeat: It is a very tame change. Were you frantic and delirious when a neural network first identified a dog in your photos? Isn't that the slippery slope to it reporting you to the authorities for something bong shaped? Speaking of which, every bit of fear mongering relies upon a slippery slope fallacy. What is clearly a PR move is somehow actually the m…

That’s not a slippery slope; that’s a fully built system just waiting for external pressure to make the slightest change. Apple’s changes would enable such screening, takedown, and reporting in its end-to-end messaging. The abuse cases are easy to imagine: governments that outlaw homosexuality might require the classifier to be trained to restrict apparent LGBTQ+ content, or an authoritarian regime might demand the c…

We can carry every single element back to its inception and make identical arguments. That's the problem with slippery slopes.

Apple - creates messaging platform.

Slippery slope - governments can force Apple to send them all messages.

Apple - creates encrypted messaging platform.

Slippery slope - governments can force Apple to send them the keys and all messages

Apple - Adds camera to device (GPS, microphone, accelerometer, step detection, etc)

Slippery slope - governments can force them to record whenever the government demands and send a live stream to the government. Or send locations, or walking patterns, or conversations.

Apple - makes operating system

Slippery slope - Basically anything. There are so many ways I could go with this. Government can force them to make a messaging and photo system, add cameras to their devices, entice users to take and accumulate pictures, and do image hashing and report suspect photos.

That's the problem with slippery slope arguments. They become meaningless rhetoric.

Image perceptual hashing is literally a single person's work for two hours. If you really think the barrier between an oppressive government stomping on groups or not is whether Apple did a (poorly communicated) Child Safety PR move and implemented this trivial mechanism...the world is a lot more perilous and scary than you think.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#234

Earlier quoted context omitted.

This on-device scanning is even worse. They cant even tell what was violating, or what hash, or what image. Just that the computer said you are violating. We have no idea about the hash collisions. When talking about whole world, 2^256 isn't a big enough space.... even if they're using 256 bits. And how dare anybody criticize this - criticism is tantamount to being for child porn. (Then again, that's why it was chose…

There is a shared (among all of the major tech companies and presumably law enforcement) hash database of child abuse material. Going from a photo to the hash is deterministic: How it gets to a hash on your phone is surely the same way it gets to a hash running the exact same algorithm on the cloud, whether iCloud, Amazon Photos, etc. Such a collision would generate a human validation. This applies to cloud-shared fi…

1. how many false positives have there been?

2. is it really reviewed by a human? I see how YT works, and automated failure at scale is the name of the game

3. apple has said that the on-device scanning only provides a binary yes/no on CP detection. How do you defend against a "yes" accusation? (when stored on someone else's server, the evidence is there)

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#235
post #193
post #182

Earlier quoted context omitted.

Yeah as I mentioned down the thread, once you act against the users, you're dead. I'm done. They are going from my life. Good job it's ebay 80% off fees this weekend here in the UK.

I mean eBay isn’t exactly free of bad behavior…

I think they're just selling their iDevices on there

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#236
post #53

Earlier quoted context omitted.

Right, my question is of course a rhetorical one. If I similarly draw other crimes being committed, the same does not apply. Why is that? And to address your explicit question, it is far too complex and specific to a given community to answer in any meaningful way here. I can tell you what isn't the answer though: deploying spyware on phones worldwide.

> If I similarly draw other crimes being committed, the same does not apply. Why is that? The answer is much more simple than you seem to think it is. Because the law doesn't say it is. I can only go by the law in my country, which is that (loosely translated) 'ownership of any image of someone looking like a minor in a sexually suggestive position' is a crime. Since a drawing is an image, it's a crime. Having an ima…

It is a pretty dumb law IMHO for the mere fact that two teenagers sexting on snapchat when they are 17 years and 355 days old are committing a fairly serious crime that can completely mess up their lives if caught but doing that the next day is totally ok all of a sudden and they can talk and laugh about it.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#237
post #9

Earlier quoted context omitted.

I think there is a very deep and troublesome philosophical issue here. Ceci n'est pas une pipe. A picture of child abuse /is not/ child abuse. Let me ask you a counter-question. If I am able to draw child pornography so realistically that you couldn't easily tell, am I committing a crime by drawing?

Yes. People have been convicted for possession of hand-drawn and computer-generated images. Editing a child's image to make it pornographic is also illegal. So some "deepfake" videos using faces from young celebs are in all likelihood very illegal in many jurisdictions. Images can be illegal if all people are of age, but are portrayed as underage. Many historical dramas take legal advice about this when they have adu…

> People have been convicted for possession of hand-drawn and computer-generated images.

If that's indeed the law in some countries, it is a stupid law that nobody should help enforce.

In Shakespeare's take on the story of Romeo and Juliet, Juliet is thirteen. So this play should probably be illegal in the countries that have such laws.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#238

Earlier quoted context omitted.

Though we were okay with Gmail doing the same because "hey, it's free!". But I understand your concern here. All our lives are now digitalised and maybe stored forever somewhere and anything you do, even if completely benign, could be considered a crime in some country or even in your own country in a few years from now.

Your gmail messages live on Google's servers. It's not ok for them to scan everything, but it's completely different from Apple scanning your phone's content.

The hashes are computed from images that live in iCloud - how is this different?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#239
Beyond the obvious here, I'm just shocked Apple thought they could do this without causing a shitstorm of biblical proportions. To market yourself as the "privacy-centric" ecosystem and then do a complete about-face requires either disarray and tone-deafness at the management level... or, alternatively, extremely nefarious intentions. I'm honestly not sure which one it is at this point, and their reaction in the coming days will probably reveal that.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#240

Earlier quoted context omitted.

Fixed further: Chinese Government: Here is the NeuralHash for some child abuse imagery, please scan this user's phone and tell us if it's found. Apple: Sure we found it. Chinese Government to some western company/instititution: We have detected unacceptable behavior from your employee/student/client/vendor. Please cancel them, or we will stop funding you.

Replace Chinese with absolutely any government and that's what'll happen. We're pretty much at a point where any hacker/leaker anywhere on earth is "found" to have committed sex crimes or have 300 gigabytes of child abuse on their computers. Eventually Disney will be getting their hands in it to detect copyrighted content and then it's all over.

Pretty sad when you trust the "bad" guys more than the "good" guys.

I'm much less concerned with on my device than I am with the governments of the world having access to it.

At least the motivations of the are generally monetary and likely don't represent a significant threat to human rights and freedom of speech.

Post reply on HN